Top
Best
New

Posted by ReturnoftheHack 2 hours ago

Two-Tier Encryption in the UK – Identical Apple Devices, Different Protection(macanorak.com)
55 points | 11 comments
Cider9986 26 minutes ago|
It's crazy SimpleX is fine being based there. I mean, everything is open, the clients have reproducible builds, but it seems like it may end up being a hassle.

Has the UK started attacking any open source E2EE projects yet?

Apple's control over iOS is the main reason I prefer GrapheneOS so much over it. You get amazing privacy and security without sacrificing control. GrapheneOS has said they won't introduce age verification and a backdoor they obviously won't implement.

codedokode 32 minutes ago||
Interesting, the government can demand creating a backdoor and doesn't let anyone tell about it. Basically, outlawing E2EE.
pirates 23 minutes ago||
If Bill left the UK temporarily would the ability to turn on ADP come back? Or is a device from the UK that’s not able to enroll somehow prevented forever? Not saying that this makes it OK, just curious
jxckstr 10 minutes ago||
You can switch your Apple ID's region to another country, enable ADP then revert your account's region back to the United Kingdom. You've got to leave Family Sharing first and may also need to adjust/cancel subscriptions - I don't think it's totally straightforward.
netsharc 4 minutes ago||
What a crazy answer you've written. In the sense of: it's wild that the procedure is like that.

It's almost as wild as when during the pandemic "lockdown", planes had to take off, burn tonnes of fuel and land empty some minutes later at the same airport, because there's some fucking law about landing spots and how they'd be lost if that bullshit wasn't done.

ReturnoftheHack 19 minutes ago|||
Yeah, good point. I wonder what would happen if someone without ADP in the UK changed over the region settings to the United States, switched ADP on, and then switched the region back to the UK. I wonder if anybody's tried this?
petcat 22 minutes ago||
I think country is associated with the iCloud/Apple ID account, not the physical device.
ABNW 33 minutes ago||
Fantastic article, and a real concern for UK Citizens.
varispeed 25 minutes ago||
Since Epstein is no more, the governments became crazy about going after people's private data, perhaps hoping to find some spice. Like some politicians lost their source.
sneak 22 minutes ago||
The Apple-vs-FBI narrative is constructed fiction. Sure, they didn't make a custom firmware to dump the phone's contents, but that's irrelevant. Everything relevant to the investigation on that phone was in the non-E2EE iCloud Backup, which the FBI got from Apple long before, via normal search warrant means. Apple likely either got an FAA702 order (aka PRISM, aka the "backdoor" that Tim Apple says doesn't exist - it allows the USG to access anyone's iCloud data immediately, with no warrant (it's not an encryption backdoor, just an access backdoor)) or a standard search warrant and most probably turned over everything they had in iCloud instantly, just as they do constantly when receiving a search warrant or FAA702 order. (As I mentioned, the FAA702 order fulfillment is likely instantaneous/automated, which amounts to direct access to the storage servers.)

The whole "Apple won't do what the USG wants" story is farce, engineered specifically to protect Apple's brand image. Following the Snowden drop when we all learned that the USG has unfettered realtime access to everything in iCloud without a warrant via FAA702, Apple had a major fucking crisis on its hands, along with a lot of other companies. (If you think the CIA can't read any object in S3, you simply don't understand how the world works. Note also that AWS has built a custom, one-off, airgapped AWS region ON PREM for the CIA. https://aws.amazon.com/federal/us-intelligence-community/ )

Those CEOs all went to DC and sat down with Obama and talked it out. The official cover story was something like "Obama wants help with healthcare.gov".

> The top leaders from the world’s biggest technology companies pressed their case for reform of the National Security Agency’s controversial surveillance operations at a meeting with President Obama on Tuesday, resisting attempts by the White House to portray the encounter as a wide-ranging discussion of broader priorities.

https://www.businessinsider.com/tech-ceo-meeting-with-obama-... (includes photo)

It is very likely that this media plan was discussed and agreed upon in those meetings. Otherwise, nobody sane in any government in Europe would ever buy an iPhone (or let their citizens do same), given that the USG can read all their photos and messages and emails and contacts in iCloud instantly and without a warrant.

(China of course requires Apple run the iCloud servers for Chinese users in China via a joint venture with a CCP-operated company, which preserves the same realtime full access to all iCloud/iMessage data in China for the CCP as PRISM does for the USG.)

Don't believe the marketing hype.

Further reading:

https://en.wikipedia.org/wiki/PRISM

The Snowden releases support very plainly the direct realtime access of the US intelligence community to tech company servers without search warrants (just FISA orders).

It is the single most used data source by the US intelligence community.

https://en.wikipedia.org/wiki/File:Prism_slide_5.jpg

Apple began providing such data in October 2012.

https://commons.wikimedia.org/wiki/File:PRISM_Collection_Det...

https://www.cnet.com/tech/tech-industry/new-slides-reveal-gr...

alt227 12 minutes ago||
Heres a favourite of mine. Apple & Google were/still are syphoning off all mobile device push messages to US government. They flat out denied it for years until it got leaked from another source, as soon as it was out in the open they admitted and said they were doing it all along but weren't allowed to tell anybody due to government NDAs.

https://www.reuters.com/technology/cybersecurity/governments...

These aren't conspiracy theories, these types of secret agreements happen all the time.

EDIT: it seems the original poster I was replying to has deleted their post, and so this may not make as much sense in the thread now.

aidio 30 minutes ago||
[flagged]
hn1rig3rak 16 minutes ago|
[dead]